Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Data Breach topic
No spam. Unsubscribe anytime.
Franklin IT director reports progress on 2024 cybersecurity breach notifications
Summary
City IT officials told the Common Council Aug. 5 they are nearing closure on the response to an Aug. 15, 2024 cybersecurity incident that exposed files on a city server and prompted mass notifications.
Get email alerts on the Cybersecurity Data Breach topic
No spam. Unsubscribe anytime.
The City of Franklin’s director of information technology told the Common Council on Aug. 5 that the city is nearing closure of its response to a cybersecurity incident first detected Aug. 15, 2024. The director summarized the investigative steps, notification process and follow-up services offered to potentially affected individuals.
Why this matters: City staff said the intruder exfiltrated approximately 52 gigabytes of data and had access to about 2 terabytes on a file server. Because the forensic team could not identify every file taken with absolute certainty, staff treated the entire file server as potentially compromised and reviewed files to determine whether personal identifiable information (PII) was present.
Investigation and notification: The city said Rapid7 initially identified the incident; the city invoked its cybersecurity insurance with Tokyo Marine as underwriter and engaged legal counsel experienced in incident response. Forensic firm SureFire and a postmortem vendor, Haystack, were retained to analyze the intrusion, confirm removal of the attacker and evaluate root cause. The city then contracted TransUnion’s CyberScout unit to mail notification letters and to operate a call center for impacted residents. The director said the city inadvertently sent letters printed in grayscale (scanning the color logo produced a low-quality header) and did not obtain proof sheets before mailing; that contributed to some recipients calling to verify authenticity.
Scope and response activity: City staff reported 13,666 letters were mailed by first-class mail; by July 31 the call center had received 122 phone calls and 198 people had enrolled in the identity-protection service offered through the insurance arrangement. The highest-volume call day was July 14, when the call center logged 52 calls and 44 enrollments. Staff said the call center will remain open through Oct. 3; the city will then begin its transition from incident response toward regular security testing with a vendor (SCS) that will perform internal and external penetration testing starting in September.
Council questions and next steps: Council members asked about steps to prevent repeat errors in notification (for example, requiring a proof sheet and clearer letterhead) and whether former employees had been affected; staff said all files with PII such as Social Security numbers or historical credit-card records had to be reviewed and, where present, recipients received notification. The director said lessons learned include requiring proof sheets for mass mailings, including clearer vendor identification ("CyberScout, TransUnion") on letters and posting FAQs online before letters are mailed. The city also set up a call center and web FAQs during the notification period to address resident questions.
Outcome: This item was presented for information only; no council action was required. The IT director said the incident-response project will be closed after Oct. 3 once vendor services wind down and that the city will proceed to scheduled penetration testing and network hardening efforts.

